<?php

namespace App\Http\Middleware;

use App\Webdisk\Model\Playlist;
use Closure;

use function App\Webdisk\makeRes;

class CheckPlaylistOwner
{
    /**
     * Handle an incoming request.
     *
     * @param  \Illuminate\Http\Request  $request
     * @param  \Closure  $next
     * @return mixed
     */
    public function handle($req, Closure $next)
    {
        $user = $req->attributes->get('user');
        $list_info = Playlist::select('owner_id')->where('id', '=', $req->input('list_id'))->first();
        if ( $list_info == null || $list_info['owner_id'] != $user->id ){
            return response(makeRes(-1, $req->input('list_id'), '不是你的歌单编号'),422);
        }
        return $next($req);
    }
}
